update master-with-bazel from master branch

This commit is contained in:
BoringSSL Robot
2024-03-05 17:16:02 +00:00
3 changed files with 4 additions and 12 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
module boringssl.googlesource.com/boringssl
go 1.19
go 1.21
require (
golang.org/x/crypto v0.17.0
-9
View File
@@ -2339,15 +2339,6 @@ func unexpectedMessageError(wanted, got any) error {
return fmt.Errorf("tls: received unexpected handshake message of type %T when waiting for %T", got, wanted)
}
func isSupportedSignatureAlgorithm(sigAlg signatureAlgorithm, sigAlgs []signatureAlgorithm) bool {
for _, s := range sigAlgs {
if s == sigAlg {
return true
}
}
return false
}
var (
// See RFC 8446, section 4.1.3.
downgradeTLS13 = []byte{0x44, 0x4f, 0x57, 0x4e, 0x47, 0x52, 0x44, 0x01}
+3 -2
View File
@@ -18,6 +18,7 @@ import (
"errors"
"fmt"
"math/big"
"slices"
)
type signer interface {
@@ -35,7 +36,7 @@ func selectSignatureAlgorithm(version uint16, key crypto.PrivateKey, config *Con
}
for _, sigAlg := range config.signSignatureAlgorithms() {
if !isSupportedSignatureAlgorithm(sigAlg, peerSigAlgs) {
if !slices.Contains(peerSigAlgs, sigAlg) {
continue
}
@@ -68,7 +69,7 @@ func signMessage(version uint16, key crypto.PrivateKey, config *Config, sigAlg s
}
func verifyMessage(version uint16, key crypto.PublicKey, config *Config, sigAlg signatureAlgorithm, msg, sig []byte) error {
if version >= VersionTLS12 && !isSupportedSignatureAlgorithm(sigAlg, config.verifySignatureAlgorithms()) {
if version >= VersionTLS12 && !slices.Contains(config.verifySignatureAlgorithms(), sigAlg) {
return errors.New("tls: unsupported signature algorithm")
}